<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Silver Tail Blog &#187; rsa conference</title>
	<atom:link href="http://silvertailsystems.wordpress.com/tag/rsa-conference/feed/" rel="self" type="application/rss+xml" />
	<link>http://silvertailsystems.wordpress.com</link>
	<description>Fighting against business logic abuse.</description>
	<lastBuildDate>Fri, 18 Dec 2009 12:11:53 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='silvertailsystems.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/577fb613fda4531b5f1cbba10427b2bb?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Silver Tail Blog &#187; rsa conference</title>
		<link>http://silvertailsystems.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://silvertailsystems.wordpress.com/osd.xml" title="Silver Tail Blog" />
		<item>
		<title>Business Logic Abuse &#8211; a recognized threat</title>
		<link>http://silvertailsystems.wordpress.com/2009/04/26/business-logic-abuse-a-recognized-threat/</link>
		<comments>http://silvertailsystems.wordpress.com/2009/04/26/business-logic-abuse-a-recognized-threat/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 01:54:19 +0000</pubDate>
		<dc:creator>Laura Mather</dc:creator>
				<category><![CDATA[Online Fraud]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[business logic abuse]]></category>
		<category><![CDATA[efraudnetwork]]></category>
		<category><![CDATA[rsa conference]]></category>
		<category><![CDATA[survey]]></category>

		<guid isPermaLink="false">http://silvertailsystems.wordpress.com/?p=532</guid>
		<description><![CDATA[The eFraudNetwork published a survey last week as part of the RSA conference.  The purpose of the survey was to &#8220;&#8230;try and understand how online fraud and data breaches are impacting multiple industries and organizations.&#8221; 
The survey covered many topics including data breaches, cross-industry information sharing, the Heartland breach, and spending to prevent fraud.
One the topics near [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=silvertailsystems.wordpress.com&blog=5811723&post=532&subd=silvertailsystems&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><img class="alignleft size-thumbnail wp-image-533" title="rsa_conference_365" src="http://silvertailsystems.files.wordpress.com/2009/04/rsa_conference_365.jpg?w=150&#038;h=55" alt="rsa_conference_365" width="150" height="55" />The eFraudNetwork published a <a href="https://365.rsaconference.com/docs/DOC-1895">survey</a> last week as part of the RSA conference.  The purpose of the survey was to &#8220;&#8230;try and understand how online fraud and data breaches are impacting multiple industries and organizations.&#8221; </p>
<p>The survey covered many topics including data breaches, cross-industry information sharing, the Heartland breach, and spending to prevent fraud.</p>
<p>One the topics near and dear to my heart was the question that asked about attack types.  The answers to this question showed that malware and viruses are at the top of people&#8217;s minds &#8211; which was to be expected.  What I didn&#8217;t expect, though, was the percent of people who said that they have seen attacks against the business logic of their website.</p>
<p>Almost 20% of people said they had seen attacks against the business logic of their site.  While this may seem like a small number to some of you, it is bigger than I was expecting.  Attacks against business logic have been going on for years, but it has only been in the last year or so that the industry is recognizing them for what they are and taking notice of them. </p>
<p>I was thrilled to see that 20% of people understand that it is the business logic of their website that is allowing attacks.  I&#8217;ll be very curious to see how this number changes when the eFN does a similar study next year, especially since it was made clear in the study that business logic attacks are one of the most dangerous attacks against a website.</p>
<p>Is anyone else surprised the number is so high?</p>
 Tagged: business logic abuse, efraudnetwork, Online Fraud, rsa conference, survey <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/silvertailsystems.wordpress.com/532/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/silvertailsystems.wordpress.com/532/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/silvertailsystems.wordpress.com/532/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/silvertailsystems.wordpress.com/532/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/silvertailsystems.wordpress.com/532/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/silvertailsystems.wordpress.com/532/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/silvertailsystems.wordpress.com/532/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/silvertailsystems.wordpress.com/532/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/silvertailsystems.wordpress.com/532/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/silvertailsystems.wordpress.com/532/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=silvertailsystems.wordpress.com&blog=5811723&post=532&subd=silvertailsystems&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://silvertailsystems.wordpress.com/2009/04/26/business-logic-abuse-a-recognized-threat/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ea92b086d3a5647be783f387715694ee?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Laura Mather</media:title>
		</media:content>

		<media:content url="http://silvertailsystems.files.wordpress.com/2009/04/rsa_conference_365.jpg?w=150" medium="image">
			<media:title type="html">rsa_conference_365</media:title>
		</media:content>
	</item>
		<item>
		<title>Blogging, again, from RSA Conference 2009</title>
		<link>http://silvertailsystems.wordpress.com/2009/04/22/blogging-again-from-rsa-conference-2009/</link>
		<comments>http://silvertailsystems.wordpress.com/2009/04/22/blogging-again-from-rsa-conference-2009/#comments</comments>
		<pubDate>Wed, 22 Apr 2009 08:12:41 +0000</pubDate>
		<dc:creator>Sherrick Murdoff</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[rsa conference]]></category>
		<category><![CDATA[threatpost]]></category>

		<guid isPermaLink="false">http://silvertailsystems.wordpress.com/?p=511</guid>
		<description><![CDATA[
At the RSA Conference 2009 &#8211; day 2.
Normally blogging from a conference I try to be upbeat and positive on the speakers (I&#8217;m usually a glass-half-full guy), but I just can&#8217;t say I was wowed today by the keynotes. A lot about collaboration &#8211; can&#8217;t go wrong there. Definitely a couple mentions about how attacks [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=silvertailsystems.wordpress.com&blog=5811723&post=511&subd=silvertailsystems&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><img class="alignleft size-thumbnail wp-image-515" title="yawn1" src="http://silvertailsystems.files.wordpress.com/2009/04/yawn1.jpg?w=80&#038;h=96" alt="yawn1" width="80" height="96" /></p>
<p>At the <a title="RSA Conference 2009" href="http://rsaconference2009/" target="_blank">RSA Conference 2009</a> &#8211; day 2.</p>
<p>Normally blogging from a conference I try to be upbeat and positive on the speakers (I&#8217;m usually a glass-half-full guy), but I just can&#8217;t say I was wowed today by the keynotes. A lot about collaboration &#8211; can&#8217;t go wrong there. Definitely a couple mentions about how attacks are now directed at the application layer &#8211; can&#8217;t agree more, this is why we have Silver Tail. However, nothing inspiring. Anyone disagree?</p>
<p>Spent much of the day in meetings with potential customers and partners &#8211; great feedback and a lot of excitement about what we are doing and about our <a href="http://www.silvertailsystems.com/index.php/pages/view/news-and-events#press_releases">announcements</a> yesterday. Personal note: I&#8217;ve noticed an interesting trend of many of my friends from the software development days are now in the security space &#8211; must be where all the innovation is happening!</p>
<p>Enjoyed <a title="Jeremiah Grossman" href="http://jeremiahgrossman.blogspot.com/" target="_blank">Jeremiah Grossman</a>&#8217;s session on web hacking techniques, though a little technical for me &#8211; but I get the picture: the list of top web hacking techniques never goes away&#8230; don&#8217;t need to be too technical to understand that. Jeremiah filled a very large room in the last session of the day (5.40pm) &#8211; testament to the speaker.</p>
<p>I did discover a new (new to me) security news site, <a title="threatpost" href="http://www.threatpost.com" target="_blank">threatpost</a>. Good format.</p>
<p>The after parties were in ernest, with even bigger ones scheduled for tomorrow night. See you there&#8230;</p>
 Tagged: rsa conference, threatpost <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/silvertailsystems.wordpress.com/511/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/silvertailsystems.wordpress.com/511/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/silvertailsystems.wordpress.com/511/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/silvertailsystems.wordpress.com/511/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/silvertailsystems.wordpress.com/511/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/silvertailsystems.wordpress.com/511/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/silvertailsystems.wordpress.com/511/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/silvertailsystems.wordpress.com/511/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/silvertailsystems.wordpress.com/511/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/silvertailsystems.wordpress.com/511/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=silvertailsystems.wordpress.com&blog=5811723&post=511&subd=silvertailsystems&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://silvertailsystems.wordpress.com/2009/04/22/blogging-again-from-rsa-conference-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9a4f40f1e603ec693ab9ec817a4ada9d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">silvertail</media:title>
		</media:content>

		<media:content url="http://silvertailsystems.files.wordpress.com/2009/04/yawn1.jpg?w=96" medium="image">
			<media:title type="html">yawn1</media:title>
		</media:content>
	</item>
		<item>
		<title>Blogging from RSA Conference 2009</title>
		<link>http://silvertailsystems.wordpress.com/2009/04/20/blogging-from-rsa-conference-2009/</link>
		<comments>http://silvertailsystems.wordpress.com/2009/04/20/blogging-from-rsa-conference-2009/#comments</comments>
		<pubDate>Tue, 21 Apr 2009 07:24:18 +0000</pubDate>
		<dc:creator>Sherrick Murdoff</dc:creator>
				<category><![CDATA[Online Fraud]]></category>
		<category><![CDATA[behavior analysis]]></category>
		<category><![CDATA[business logic abuse]]></category>
		<category><![CDATA[rsa conference]]></category>

		<guid isPermaLink="false">http://silvertailsystems.wordpress.com/?p=498</guid>
		<description><![CDATA[We are at the RSA Conference 2009 starting today with a couple of interesting pre-conference events.
First, the eFraudNetwork meeting was held today where Laura Mather moderated a panel of fraud experts from Bank of America, Yahoo! and Medicare/Medicaid. The panel discussed ideas and best practices for protecting customers &#8211; everything from encrypting data, education and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=silvertailsystems.wordpress.com&blog=5811723&post=498&subd=silvertailsystems&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="http://www.rsaconference.com/2009/us/index.htm"><img class="alignleft size-thumbnail wp-image-500" title="rsa09-logo" src="http://silvertailsystems.files.wordpress.com/2009/04/rsa09-logo.jpg?w=128&#038;h=35" alt="rsa09-logo" width="128" height="35" /></a>We are at the <a title="RSA Conference 2009" href="http://www.rsaconference.com/2009/us/index.htm" target="_blank">RSA Conference 2009</a> starting today with a couple of interesting pre-conference events.<a href="http://www.rsa.com/node.aspx?id=3071"><img class="alignright size-thumbnail wp-image-501" title="efraudnetwork" src="http://silvertailsystems.files.wordpress.com/2009/04/efraudnetwork.gif?w=90&#038;h=54" alt="efraudnetwork" width="90" height="54" /></a></p>
<p>First, the <a title="eFraudNetwork" href="http://www.rsa.com/node.aspx?id=3071" target="_blank">eFraudNetwork</a> meeting was held today where Laura Mather moderated a panel of fraud experts from Bank of America, Yahoo! and Medicare/Medicaid. The panel discussed ideas and best practices for protecting customers &#8211; everything from encrypting data, education and awareness, and tracking perpetrators of online crime. The panel was titled, &#8220;Protecting Customers: Case Studies from Leading Enterprises.&#8221;</p>
<p>The <a title="Innovation Sandbox" href="http://www.rsaconference.com/2009/us/highlights/innovation-sandbox.htm" target="_blank">Innovation Sandbox</a> was held highlighting ten (out of 50+) new companies who had creative ideas in the area of security. A good mini-conference to help promote the new, young startups get a little more attention. A couple of interesting companies, in my opinion, include <a title="Purewire" href="http://www.purewire.com" target="_blank">Purewire</a> (SaaS-based protection for enterprise client machines) and <a title="Behaviosec" href="http://www.behaviosec.com" target="_blank">Behaviosec</a> (behavior analysis of the user on how they interact with their machine: typing, mouse movements, etc.). The most entertaining was seeing the executives pitch their company in 3 minutes, which the winner, <a title="AlertEnterprise" href="http://www.alertenterprise.com" target="_blank">AlertEnterprise</a>, did just that &#8211; plus, they had the best visually appealing application &#8211; hard to beat 3-D images.</p>
<p>Lastly, the welcome reception was a good way to get started on seeing the expo floor&#8230; booth discussions are so much better done over a beer.</p>
<p>Looking forward to tomorrow&#8217;s keynotes and <a title="Jeremiah Grossman" href="http://jeremiahgrossman.blogspot.com/" target="_blank">Jeremiah Grossman</a>&#8217;s Top Ten Web Hacking Techniques of 2008 &#8211; usually some good <a title="Business Logic Abuse" href="http://en.wikipedia.org/wiki/Business_logic_abuse" target="_blank">business logic abuse</a> in there!</p>
 Tagged: business logic abuse, Online Fraud, rsa conference <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/silvertailsystems.wordpress.com/498/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/silvertailsystems.wordpress.com/498/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/silvertailsystems.wordpress.com/498/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/silvertailsystems.wordpress.com/498/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/silvertailsystems.wordpress.com/498/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/silvertailsystems.wordpress.com/498/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/silvertailsystems.wordpress.com/498/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/silvertailsystems.wordpress.com/498/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/silvertailsystems.wordpress.com/498/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/silvertailsystems.wordpress.com/498/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=silvertailsystems.wordpress.com&blog=5811723&post=498&subd=silvertailsystems&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://silvertailsystems.wordpress.com/2009/04/20/blogging-from-rsa-conference-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9a4f40f1e603ec693ab9ec817a4ada9d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">silvertail</media:title>
		</media:content>

		<media:content url="http://silvertailsystems.files.wordpress.com/2009/04/rsa09-logo.jpg?w=128" medium="image">
			<media:title type="html">rsa09-logo</media:title>
		</media:content>

		<media:content url="http://silvertailsystems.files.wordpress.com/2009/04/efraudnetwork.gif?w=128" medium="image">
			<media:title type="html">efraudnetwork</media:title>
		</media:content>
	</item>
		<item>
		<title>2009 RSA Conference &#8211; eFraudNetwork</title>
		<link>http://silvertailsystems.wordpress.com/2009/04/20/2009-rsa-conference-efraudnetwork/</link>
		<comments>http://silvertailsystems.wordpress.com/2009/04/20/2009-rsa-conference-efraudnetwork/#comments</comments>
		<pubDate>Mon, 20 Apr 2009 19:26:29 +0000</pubDate>
		<dc:creator>Laura Mather</dc:creator>
				<category><![CDATA[business logic abuse]]></category>
		<category><![CDATA[application logic attacks]]></category>
		<category><![CDATA[efraudnetwork]]></category>
		<category><![CDATA[rsa conference]]></category>

		<guid isPermaLink="false">http://silvertailsystems.wordpress.com/?p=482</guid>
		<description><![CDATA[I have the privilege of attending the eFraudNetwork day as part of the 2009 RSA security conference.  Prior to the conference, the eFN people had done a survey on the attacks banks and other websites are seeing.  Most of the data wasn&#8217;t surprising: identity theft was a big one.
Something that was surprising, though, was that almost 20% [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=silvertailsystems.wordpress.com&blog=5811723&post=482&subd=silvertailsystems&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><img class="alignleft size-full wp-image-484" title="rsa" src="http://silvertailsystems.files.wordpress.com/2009/04/rsa.jpg?w=180&#038;h=59" alt="rsa" width="180" height="59" />I have the privilege of attending the eFraudNetwork day as part of the 2009 RSA security conference.  Prior to the conference, the eFN people had done a survey on the attacks banks and other websites are seeing.  Most of the data wasn&#8217;t surprising: identity theft was a big one.</p>
<p>Something that was surprising, though, was that almost 20% of respondents saw attacks against application logic.  When I saw that question in the survey I was worried that people wouldn&#8217;t know how to define application logic attacks.  It was very interesting that people are definitely seeing this type of attack.</p>
<p>While 20% seems small, my hypothesis is that most people are getting hit by this type of attack, but 1) many of them don&#8217;t know what they are called and 2) many of them don&#8217;t understand yet that their websites are being impacted by this type of attack.</p>
<p>I&#8217;ll be anxious to see the results of this study going forward to see how this number changes.</p>
 Tagged: application logic attacks, efraudnetwork, rsa conference <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/silvertailsystems.wordpress.com/482/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/silvertailsystems.wordpress.com/482/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/silvertailsystems.wordpress.com/482/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/silvertailsystems.wordpress.com/482/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/silvertailsystems.wordpress.com/482/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/silvertailsystems.wordpress.com/482/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/silvertailsystems.wordpress.com/482/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/silvertailsystems.wordpress.com/482/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/silvertailsystems.wordpress.com/482/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/silvertailsystems.wordpress.com/482/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=silvertailsystems.wordpress.com&blog=5811723&post=482&subd=silvertailsystems&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://silvertailsystems.wordpress.com/2009/04/20/2009-rsa-conference-efraudnetwork/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ea92b086d3a5647be783f387715694ee?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Laura Mather</media:title>
		</media:content>

		<media:content url="http://silvertailsystems.files.wordpress.com/2009/04/rsa.jpg" medium="image">
			<media:title type="html">rsa</media:title>
		</media:content>
	</item>
	</channel>
</rss>